SYMBOL | COMMON_NAME | aka. SYNONYMS |
Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Duuzer, and Hangman.
2025-02-05
⋅
Bitdefender
⋅
Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam tsunami |
2024-12-26
⋅
⋅
Weixin
⋅
Analysis of the attack activities of APT-C-26 (Lazarus) using weaponized IPMsg software ComeBacker |
2024-11-17
⋅
Post about Tsunami tsunami |
2024-10-30
⋅
Palo Alto Networks Unit 42
⋅
Jumpy Pisces Engages in Play Ransomware Dtrack MimiKatz PLAY Sliver |
2024-10-23
⋅
ANY.RUN
⋅
DarkComet RAT: Technical Analysis of Attack Chain DarkComet |
2024-10-13
⋅
Doubleagent.net
⋅
FASTCash for Linux FastCash |
2024-10-03
⋅
Virus Bulletin
⋅
Sugarcoating KANDYKORN: a sweet dive into a sophisticated MacOS backdoor HLOADER KANDYKORN SUGARLOADER |
2024-09-19
⋅
Gen Digital
⋅
Evolution of Lazarus ‘FudModule - no longer (stand)alone’ FudModule |
2024-08-30
⋅
Microsoft
⋅
North Korean threat actor Citrine Sleet exploiting Chromium zero-day FudModule |
2024-07-29
⋅
Mandiant
⋅
UNC4393 Goes Gently into the SILENTNIGHT Black Basta QakBot sRDI SystemBC Zloader UNC4393 |
2024-07-10
⋅
Akamai
⋅
CVE-2024-4577 Exploits in the Wild One Day After Disclosure Tsunami Ghost RAT xmrig |
2024-07-05
⋅
⋅
Weixin
⋅
APT-C-26 (Lazarus) uses PyPI to attack Windows, Linux, and macOS platforms SimpleTea SimpleTea |
2024-05-23
⋅
Palo Alto Networks Unit 42
⋅
Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia Agent Racoon CHINACHOPPER Ghost RAT JuicyPotato MimiKatz Ntospy PlugX SweetSpecter TunnelSpecter CL-STA-0043 |
2024-04-18
⋅
Avast
⋅
From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams FudModule |
2024-02-29
⋅
Vipyr Security
⋅
Novel ELF64 Remote Access Tool Embedded in Malicious PyPI Uploads SimpleTea |
2024-02-28
⋅
Avast Decoded
⋅
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day FudModule |
2024-01-05
⋅
Twitter (@greglesnewich)
⋅
Tweets about a SpectralBlur a macOS sample SpectralBlur |
2024-01-05
⋅
Twitter (@X__Junior)
⋅
Tweet about a SpectralBlur Linux sample SpectralBlur |
2023-12-05
⋅
Kaspersky Labs
⋅
BlueNoroff: new Trojan attacking macOS users RustBucket |
2023-11-27
⋅
SentinelOne
⋅
DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads HLOADER KANDYKORN RustBucket SUGARLOADER |
2023-11-22
⋅
Microsoft
⋅
Diamond Sleet supply chain compromise distributes a modified CyberLink installer LambLoad |
2023-11-20
⋅
PWC
⋅
King of Thieves: Black Alicanto and the Ecosystem of North Korea-Based Cyber Operations RustBucket CageyChameleon RustBucket |
2023-11-10
⋅
⋅
HAURI
⋅
Detailed analysis report: Malware disguised as Putty (Lazarus APT) ComeBacker |
2023-10-31
⋅
Elastic
⋅
Elastic catches DPRK passing out KANDYKORN HLOADER KANDYKORN SUGARLOADER |
2023-10-27
⋅
Kaspersky
⋅
A cascade of compromise: unveiling Lazarus’ new campaign LPEClient PostNapTea |
2023-10-26
⋅
ESET Research
⋅
ESET APT Activity Report Q2–Q3 2023 SimpleTea LODEINFO |
2023-10-18
⋅
Microsoft
⋅
Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability FeedLoad ForestTiger HazyLoad RollSling Silent Chollima |
2023-10-18
⋅
Kaspersky Labs
⋅
Updated MATA attacks industrial companies in Eastern Europe Dacls Unidentified 106 |
2023-10-17
⋅
⋅
AhnLab
⋅
Lazarus Group’s Operation Dream Magic LazarDoor wAgentTea |
2023-10-13
⋅
AhnLab
⋅
Analysis Report on Lazarus Threat Group’s Volgmer and Scout Malware JessieConTea Scout Volgmer |
2023-10-04
⋅
Virus Bulletin
⋅
Lazarus Campaigns and Backdoors in 2022-23 SimpleTea POOLRAT 3CX Backdoor BLINDINGCAN CLOUDBURST DRATzarus ForestTiger ImprudentCook LambLoad LightlessCan miniBlindingCan PostNapTea SnatchCrypto wAgentTea WebbyTea WinInetLoader |
2023-09-29
⋅
ESET Research
⋅
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company CLOUDBURST LightlessCan miniBlindingCan sRDI |
2023-09-27
⋅
Positive Technologies
⋅
Dark River. You can't see them, but they're there Dacls Unidentified 106 |
2023-09-22
⋅
Mandiant
⋅
Backchannel Diplomacy: APT29’s Rapidly Evolving Diplomatic Phishing Operations Brute Ratel C4 Cobalt Strike EnvyScout GraphDrop QUARTERRIG sRDI Unidentified 107 (APT29) |
2023-08-31
⋅
AhnLab
⋅
Analysis of Andariel’s New Attack Activities Andardoor BlackRemote Tiger RAT Volgmer |
2023-08-30
⋅
Kaspersky Labs
⋅
IT threat evolution in Q2 2023 3CX Backdoor Bankshot BLINDINGCAN GoldMax Kazuar QUIETCANARY tomiris GoldenJackal |
2023-08-22
⋅
⋅
AhnLab
⋅
Analyzing the new attack activity of the Andariel group Andardoor MimiKatz QuiteRAT Tiger RAT Volgmer |
2023-07-05
⋅
SentinelOne
⋅
BlueNoroff | How DPRK’s macOS RustBucket Seeks to Evade Analysis and Detection RustBucket |
2023-06-29
⋅
Elastic
⋅
The DPRK strikes using a new variant of RUSTBUCKET RustBucket |
2023-06-08
⋅
⋅
AhnLab
⋅
Lazarus Group exploiting vulnerabilities in domestic financial security solutions LazarDoor LazarLoader |
2023-05-25
⋅
YouTube (BSidesCharm)
⋅
it’s all Magic(RAT) – A look into recent North Korean nation-state attacks MagicRAT VSingle YamaBot |
2023-05-22
⋅
Sekoia
⋅
Bluenoroff’s RustBucket campaign RustBucket WebbyTea |
2023-05-01
⋅
JPCERT/CC
⋅
Attack trends related to the attack campaign DangerousPassword RustBucket CageyChameleon Cur1Downloader SnatchCrypto |
2023-04-24
⋅
Cofense
⋅
Open-Source Gh0st RAT Still Haunting Inboxes 15 Years After Release Ghost RAT |
2023-04-21
⋅
Jamf Blog
⋅
BlueNoroff APT group targets macOS with ‘RustBucket’ Malware RustBucket |
2023-04-21
⋅
Symantec
⋅
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe VEILEDSIGNAL |
2023-04-20
⋅
3CX
⋅
Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found POOLRAT |
2023-04-20
⋅
Mandiant
⋅
3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible POOLRAT IconicStealer UNC4736 |
2023-04-20
⋅
ESET Research
⋅
Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack BADCALL SimpleTea POOLRAT 3CX Backdoor BADCALL IconicStealer |
2023-04-18
⋅
Mandiant
⋅
M-Trends 2023 QUIETEXIT AppleJeus Black Basta BlackCat CaddyWiper Cobalt Strike Dharma HermeticWiper Hive INDUSTROYER2 Ladon LockBit Meterpreter PartyTicket PlugX QakBot REvil Royal Ransom SystemBC WhisperGate |
2023-04-13
⋅
Intel 471
⋅
From GhostNet to PseudoManuscrypt - The evolution of Gh0st RAT BBSRAT Gh0stTimes Ghost RAT PseudoManuscrypt |
2023-04-12
⋅
Kaspersky Labs
⋅
Following the Lazarus group by tracking DeathNote campaign Bankshot BLINDINGCAN ForestTiger LambLoad LPEClient MimiKatz NedDnLoader Racket Downloader Volgmer |
2023-04-03
⋅
Twitter (@kucher1n)
⋅
Tweet on an alternative Guporam sample Gopuram |
2023-04-03
⋅
Youtube (MalwareAnalysisForHedgehogs)
⋅
Malware Analysis - 3CX SmoothOperator ffmpeg.dll with Binary Ninja 3CX Backdoor |
2023-04-03
⋅
Kaspersky Labs
⋅
Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack Gopuram |
2023-04-01
⋅
Github (dodo-sec)
⋅
SmoothOperator 3CX Backdoor |
2023-04-01
⋅
Objective-See
⋅
Ironing out (the macOS) details of a Smooth Operator (Part II) 3CX Backdoor |
2023-03-31
⋅
splunk
⋅
Splunk Insights: Investigating the 3CXDesktopApp Supply Chain Compromise 3CX Backdoor |
2023-03-31
⋅
cyble
⋅
A Comprehensive Analysis of the 3CX Attack 3CX Backdoor |
2023-03-31
⋅
Reversing Labs
⋅
Red flags flew over software supply chain-compromised 3CX update 3CX Backdoor |
2023-03-31
⋅
Blackberry
⋅
Initial Implants and Network Analysis Suggest the 3CX Supply Chain Operation Goes Back to Fall 2022 3CX Backdoor |
2023-03-31
⋅
Zscaler
⋅
3CX Supply Chain Attack Campaign Campaign Analysis 3CX Backdoor |
2023-03-31
⋅
Group-IB
⋅
36gate: supply chain attack 3CX Backdoor |
2023-03-31
⋅
vmware
⋅
Investigating 3CX Desktop Application Attacks: What You Need to Know 3CX Backdoor |
2023-03-30
⋅
OALabs
⋅
3CX Supply Chain Attack 3CX Backdoor |
2023-03-30
⋅
Trend Micro
⋅
Developing Story: Information on Attacks Involving 3CX Desktop App 3CX Backdoor IconicStealer |
2023-03-30
⋅
Fortiguard
⋅
3CX Desktop App Compromised (CVE-2023-29059) 3CX Backdoor |
2023-03-30
⋅
CrowdStrike
⋅
2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers 3CX Backdoor |
2023-03-30
⋅
Cado Security
⋅
Forensic Triage of a Windows System running the Backdoored 3CX Desktop App 3CX Backdoor |
2023-03-30
⋅
Volexity
⋅
3CX Supply Chain Compromise Leads to ICONIC Incident 3CX Backdoor IconicStealer |
2023-03-30
⋅
Elastic
⋅
Elastic users protected from SUDDENICON’s supply chain attack 3CX Backdoor |
2023-03-30
⋅
Rapid7 Labs
⋅
Backdoored 3CXDesktopApp Installer Used in Active Threat Campaign 3CX Backdoor |
2023-03-30
⋅
Huntress Labs
⋅
3CX VoIP Software Compromise & Supply Chain Threats 3CX Backdoor |
2023-03-30
⋅
Symantec
⋅
3CX: Supply Chain Attack Affects Thousands of Users Worldwide 3CX Backdoor IconicStealer |
2023-03-29
⋅
SentinelOne
⋅
SmoothOperator | Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack 3CX Backdoor |
2023-03-29
⋅
Objective-See
⋅
Ironing out (the macOS details) of a Smooth Operator 3CX Backdoor |
2023-03-29
⋅
CrowdStrike
⋅
CrowdStrike Falcon Platform Detects and Prevents Active Intrusion Campaign Targeting 3CXDesktopApp Customers 3CX Backdoor |
2023-03-20
⋅
SecurityIntelligence
⋅
When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule FudModule |
2023-03-09
⋅
Mandiant
⋅
Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 CLOUDBURST TOUCHMOVE TOUCHSHIFT UNC2970 |
2023-03-09
⋅
Mandiant
⋅
Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW FudModule |
2023-02-23
⋅
Bitdefender
⋅
Technical Advisory: Various Threat Actors Targeting ManageEngine Exploit CVE-2022-47966 Cobalt Strike DarkComet QuiteRAT RATel |
2023-02-23
⋅
ESET Research
⋅
WinorDLL64: A backdoor from the vast Lazarus arsenal? WinorDLL64 |
2023-02-21
⋅
SecurityIntelligence
⋅
Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers FudModule |
2023-02-09
⋅
#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities Dtrack MagicRAT Maui Ransomware SiennaBlue SiennaPurple Tiger RAT YamaBot |
2023-02-02
⋅
WithSecure
⋅
No Pineapple! –DPRK Targeting of Medical Research and Technology Sector Dtrack GREASE QuiteRAT |
2023-01-25
⋅
Proofpoint
⋅
TA444: The APT Startup Aimed at Acquisition (of Your Funds) CageyChameleon Lazarus Group TA444 |
2023-01-05
⋅
AttackIQ
⋅
Emulating the Highly Sophisticated North Korean Adversary Lazarus Group MagicRAT Tiger RAT |
2022-12-27
⋅
Kaspersky
⋅
BlueNoroff introduces new methods bypassing MoTW LazarLoader Unidentified 101 (Lazarus?) |
2022-12-20
⋅
K7 Security
⋅
Lazarus APT’s Operation Interception Uses Signed Binary Interception |
2022-12-16
⋅
Sekoia
⋅
The DPRK delicate sound of cyber AppleJeus AppleJeus SnatchCrypto |
2022-11-29
⋅
⋅
Qianxin
⋅
Job hunting trap: Analysis of Lazarus attack activities using recruitment information such as Mizuho Bank of Japan as bait CageyChameleon Cur1Downloader |
2022-11-23
⋅
Twitter (@RedDrip7)
⋅
Tweets about potential Lazarus sample Unidentified 101 (Lazarus?) |
2022-11-21
⋅
vmware
⋅
Threat Analysis: Active C2 Discovery Using Protocol Emulation Part4 (Dacls, aka MATA) Dacls |
2022-11-15
⋅
Kaspersky Labs
⋅
DTrack activity targeting Europe and Latin America Dtrack |
2022-10-24
⋅
⋅
AhnLab
⋅
Malware infection case of Lazarus attack group that neutralizes antivirus program with BYOVD technique FudModule LazarDoor Racket Downloader |
2022-09-30
⋅
ESET Research
⋅
Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium BLINDINGCAN FudModule HTTP(S) uploader LambLoad TOUCHMOVE |
2022-09-30
⋅
Virus Bulletin
⋅
Lazarus & BYOVD: evil to the Windows core FudModule |
2022-09-29
⋅
Microsoft
⋅
ZINC weaponizing open-source software BLINDINGCAN CLOUDBURST miniBlindingCan |
2022-09-26
⋅
CrowdStrike
⋅
The Anatomy of Wiper Malware, Part 3: Input/Output Controls CaddyWiper DEADWOOD DistTrack DoubleZero DUSTMAN HermeticWiper IsaacWiper Meteor Petya Sierra(Alfa,Bravo, ...) StoneDrill WhisperGate ZeroCleare |
2022-09-26
⋅
SentinelOne
⋅
Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto Interception |
2022-09-22
⋅
AhnLab
⋅
Analysis Report on Lazarus Group's Rootkit Attack Using BYOVD FudModule |
2022-09-15
⋅
Symantec
⋅
Webworm: Espionage Attackers Testing and Using Older Modified RATs 9002 RAT Ghost RAT Trochilus RAT |
2022-09-14
⋅
Mandiant
⋅
It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp BLINDINGCAN miniBlindingCan sRDI |
2022-09-10
⋅
⋅
Malverse
⋅
Realizziamo un C&C Server in Python (Bankshot) Bankshot |
2022-09-08
⋅
Cisco Talos
⋅
Lazarus and the tale of three RATs MagicRAT MimiKatz VSingle YamaBot |
2022-09-07
⋅
Cisco Talos
⋅
MagicRAT: Lazarus’ latest gateway into victim networks MagicRAT Tiger RAT |
2022-08-16
⋅
Twitter (@ESETresearch)
⋅
Twitter thread about Operation In(ter)ception for macOS Interception |
2022-08-15
⋅
Brandefense
⋅
Lazarus APT Group (APT38) AppleJeus AppleJeus BADCALL Bankshot BLINDINGCAN DRATzarus Dtrack KEYMARBLE Sierra(Alfa,Bravo, ...) Torisma WannaCryptor |
2022-08-13
⋅
YoutTube (Blue Team Village)
⋅
Attribution and Bias: My terrible mistakes in threat intelligence attribution AppleJeus Olympic Destroyer |
2022-08-12
⋅
CrowdStrike
⋅
The Anatomy of Wiper Malware, Part 1: Common Techniques Apostle CaddyWiper DEADWOOD DistTrack DoubleZero DUSTMAN HermeticWiper IsaacWiper IsraBye KillDisk Meteor Olympic Destroyer Ordinypt Petya Sierra(Alfa,Bravo, ...) StoneDrill WhisperGate ZeroCleare |
2022-08-12
⋅
Brandefense
⋅
Mythic Leopard APT Group Crimson RAT DarkComet NjRAT Oblique RAT Peppy RAT |
2022-08-09
⋅
Kaspersky
⋅
Andariel deploys DTrack and Maui ransomware Dtrack Maui Ransomware |
2022-07-18
⋅
Palo Alto Networks Unit 42
⋅
Iron Taurus CHINACHOPPER Ghost RAT Wonknu ZXShell APT27 |
2022-07-14
⋅
Proofpoint
⋅
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media Chinoxy APT31 Lazarus Group TA482 |
2022-07-05
⋅
JPCERT/CC
⋅
VSingle malware that obtains C2 server information from GitHub VSingle |
2022-06-21
⋅
Cisco Talos
⋅
Avos ransomware group expands with new attack arsenal AvosLocker Cobalt Strike DarkComet MimiKatz |
2022-06-17
⋅
Github (monoxgas)
⋅
sRDI - Shellcode Reflective DLL Injection sRDI |
2022-05-23
⋅
Trend Micro
⋅
Operation Earth Berberoka reptile oRAT Ghost RAT PlugX pupy Earth Berberoka |
2022-05-09
⋅
cocomelonc
⋅
Malware development: persistence - part 4. Windows services. Simple C++ example. Anchor AppleJeus Attor BBSRAT BlackEnergy Carbanak Cobalt Strike DuQu |
2022-05-05
⋅
NCC Group
⋅
North Korea’s Lazarus: their initial access trade-craft using social media and social engineering LCPDot |
2022-04-27
⋅
Symantec
⋅
Stonefly: North Korea-linked Spying Operation Continues to Hit High-value Targets Dtrack VSingle |
2022-04-27
⋅
Trend Micro
⋅
New APT Group Earth Berberoka Targets Gambling Websites With Old and New Malware HelloBot AsyncRAT Ghost RAT HelloBot PlugX Quasar RAT Earth Berberoka |
2022-04-27
⋅
Trendmicro
⋅
Operation Gambling Puppet reptile oRAT AsyncRAT Cobalt Strike DCRat Ghost RAT PlugX Quasar RAT Trochilus RAT Earth Berberoka |
2022-04-26
⋅
Trend Micro
⋅
How Cybercriminals Abuse Cloud Tunneling Services AsyncRAT Cobalt Strike DarkComet Meterpreter Nanocore RAT |
2022-04-26
⋅
AhnLab
⋅
New Malware of Lazarus Threat Actor Group Exploiting INITECH Process Racket Downloader wAgentTea |
2022-04-20
⋅
CISA
⋅
TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Bankshot TraderTraitor |
2022-04-18
⋅
CISA
⋅
AA22-108A: TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (PDF) FastCash Bankshot |
2022-04-18
⋅
CISA
⋅
Alert (AA22-108A): TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies Bankshot |
2022-04-15
⋅
Center for Internet Security
⋅
Top 10 Malware March 2022 Mirai Shlayer Agent Tesla Ghost RAT Nanocore RAT SectopRAT solarmarker Zeus |
2022-04-14
⋅
Symantec
⋅
Lazarus Targets Chemical Sector Racket Downloader |
2022-04-01
⋅
The Hacker News
⋅
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit Fire Chili Ghost RAT |
2022-03-31
⋅
Kaspersky
⋅
Lazarus Trojanized DeFi app for delivering malware JessieConTea LCPDot |
2022-03-30
⋅
Fortinet
⋅
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits Fire Chili Ghost RAT |
2022-03-17
⋅
Sophos
⋅
The Ransomware Threat Intelligence Center ATOMSILO Avaddon AvosLocker BlackKingdom Ransomware BlackMatter Conti Cring DarkSide dearcry Dharma Egregor Entropy Epsilon Red Gandcrab Karma LockBit LockFile Mailto Maze Nefilim RagnarLocker Ragnarok REvil RobinHood Ryuk SamSam Snatch WannaCryptor WastedLocker |
2022-03-16
⋅
AhnLab
⋅
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers Ghost RAT Kingminer |
2022-03-01
⋅
Github (0xZuk0)
⋅
Malware Analysis Report: WannaCry Ransomware WannaCryptor |
2022-02-11
⋅
Cisco Talos
⋅
Threat Roundup for February 4 to February 11 DarkComet Ghost RAT Loki Password Stealer (PWS) Tinba Tofsee Zeus |
2022-02-09
⋅
SentinelOne
⋅
Modified Elephant APT and a Decade of Fabricating Evidence DarkComet Incubator NetWire RC |
2022-02-09
⋅
Sentinel LABS
⋅
ModifiedElephant APT and a Decade of Fabricating Evidence DarkComet Incubator NetWire RC ModifiedElephant |
2022-01-31
⋅
Cyber Geeks
⋅
A Detailed Analysis Of Lazarus APT Malware Disguised As Notepad++ Shell Extension AnchorMTea |
2022-01-13
⋅
Kaspersky Labs
⋅
The BlueNoroff cryptocurrency hunt is still on CageyChameleon SnatchCrypto WebbyTea |
2021-12-14
⋅
Trend Micro
⋅
Collecting In the Dark: Tropic Trooper Targets Transportation and Government ChiserClient Ghost RAT Lilith Quasar RAT xPack APT23 |
2021-12-01
⋅
⋅
ThreatBook
⋅
The Lazarus Group suspected of expanding its arsenal? The hackers target aviation industry and researchers AnchorMTea |
2021-11-10
⋅
⋅
AhnLab
⋅
Analysis Report of Lazarus Group’s NukeSped Malware DarkComet Tiger RAT |
2021-10-11
⋅
Telsy
⋅
Lazarus Group continues AppleJeus Operation AppleJeus |
2021-10-08
⋅
Virus Bulletin
⋅
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections Dacls AppleJeus AppleJeus Bankshot BookCodes RAT Dacls DRATzarus LCPDot LPEClient |
2021-10-07
⋅
Virus Bulletin
⋅
Operation Bookcodes – targeting South Korea BookCodes RAT LPEClient |
2021-10-05
⋅
Blackberry
⋅
Drawing a Dragon: Connecting the Dots to Find APT41 Cobalt Strike Ghost RAT |
2021-10-04
⋅
JPCERT/CC
⋅
Malware Gh0stTimes Used by BlackTech Gh0stTimes Ghost RAT |
2021-09-07
⋅
LIFARS
⋅
A Detailed Analysis of Lazarus’ RAT Called FALLCHILL Volgmer |
2021-09-06
⋅
cocomelonc
⋅
AV engines evasion for C++ simple malware: part 2 Agent Tesla Amadey Anchor AnchorMTea Carbanak Carberp Cardinal RAT Felixroot Konni Loki Password Stealer (PWS) Maze |
2021-09-04
⋅
cocomelonc
⋅
AV engines evasion for C++ simple malware: part 1 4h_rat Azorult BADCALL BadNews BazarBackdoor Cardinal RAT |
2021-08-22
⋅
⋅
media.ccc.de
⋅
The Bangladesh cyber bank robbery: Tracking down major criminals with malware analysis DYEPACK |
2021-08-22
⋅
Malware and Stuff
⋅
PEB: Where Magic Is Stored Dacls |
2021-08-05
⋅
KrebsOnSecurity
⋅
Ransomware Gangs and the Name Game Distraction DarkSide RansomEXX Babuk Cerber Conti DarkSide DoppelPaymer Egregor FriedEx Gandcrab Hermes Maze RansomEXX REvil Ryuk Sekhmet |
2021-07-10
⋅
Youtube (AhmedS Kasmani)
⋅
Analysis of AppleJeus Malware by Lazarus Group AppleJeus |
2021-07-08
⋅
Medium s2wlab
⋅
Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea Racket Downloader |
2021-06-15
⋅
Kaspersky
⋅
Andariel evolves to target South Korea with ransomware BISTROMATH PEBBLEDASH SHATTEREDGLASS TigerLite Tiger RAT |
2021-05-13
⋅
⋅
AhnLab
⋅
APT attack for domestic companies using library files ImprudentCook |
2021-05-11
⋅
⋅
Qianxin
⋅
Analysis of a series of attacks by the suspected Lazarus organization using Daewoo Shipyard as relevant bait BISTROMATH TigerLite |
2021-05-05
⋅
Zscaler
⋅
Catching RATs Over Custom Protocols Analysis of top non-HTTP/S threats Agent Tesla AsyncRAT Crimson RAT CyberGate Ghost RAT Nanocore RAT NetWire RC NjRAT Quasar RAT Remcos |
2021-04-28
⋅
Trend Micro
⋅
Water Pamola Attacked Online Shops Via Malicious Orders Ghost RAT |
2021-04-19
⋅
Malwarebytes
⋅
Lazarus APT conceals malicious code within BMP image to drop its RAT BISTROMATH |
2021-04-15
⋅
AhnLab
⋅
Operation Dream Job Targeting Job Seekers in South Korea LCPDot Torisma |
2021-04-08
⋅
ESET Research
⋅
(Are you) afreight of the dark? Watch out for Vyveva, new Lazarus backdoor Vyveva RAT |
2021-04-02
⋅
Dr.Web
⋅
Study of targeted attacks on Russian research institutes Cotx RAT Ghost RAT TA428 |
2021-04-01
⋅
AhnLab
⋅
ASEC REPORT VOL.102 Q1 2021 ComeBacker JessieConTea LCPDot |
2021-03-22
⋅
JPCERT/CC
⋅
Lazarus Attack Activities Targeting Japan (VSingle/ValeforBeta) VSingle |
2021-03-21
⋅
Blackberry
⋅
2021 Threat Report Bashlite FritzFrog IPStorm Mirai Tsunami elf.wellmess AppleJeus Dacls EvilQuest Manuscrypt Astaroth BazarBackdoor Cerber Cobalt Strike Emotet FinFisher RAT Kwampirs MimiKatz NjRAT Ryuk SmokeLoader TrickBot |
2021-03-15
⋅
Sophos Labs
⋅
DearCry ransomware attacks exploit Exchange server vulnerabilities dearcry WannaCryptor |
2021-03-03
⋅
SYGNIA
⋅
Lazarus Group’s MATA Framework Leveraged to Deploy TFlower Ransomware Dacls Dacls Dacls TFlower |
2021-02-28
⋅
PWC UK
⋅
Cyber Threats 2020: A Year in Retrospect elf.wellmess FlowerPower PowGoop 8.t Dropper Agent.BTZ Agent Tesla Appleseed Ave Maria Bankshot BazarBackdoor BLINDINGCAN Chinoxy Conti Cotx RAT Crimson RAT DUSTMAN Emotet FriedEx FunnyDream Hakbit Mailto Maze METALJACK Nefilim Oblique RAT Pay2Key PlugX QakBot REvil Ryuk StoneDrill StrongPity SUNBURST SUPERNOVA TrickBot TurlaRPC Turla SilentMoon WastedLocker WellMess Winnti ZeroCleare APT10 APT23 APT27 APT31 APT41 BlackTech BRONZE EDGEWOOD Inception Framework MUSTANG PANDA Red Charon Red Nue Sea Turtle Tonto Team |
2021-02-26
⋅
YouTube (Black Hat)
⋅
FASTCash and INJX_Pure: How Threat Actors Use Public Standards for Financial Fraud FastCash |
2021-02-25
⋅
Kaspersky Labs
⋅
Lazarus targets defense industry with ThreatNeedle HTTP(S) uploader LPEClient Volgmer |
2021-02-25
⋅
Intezer
⋅
Year of the Gopher A 2020 Go Malware Round-Up NiuB WellMail elf.wellmess ArdaMax AsyncRAT CyberGate DarkComet Glupteba Nanocore RAT Nefilim NjRAT Quasar RAT WellMess Zebrocy |
2021-02-23
⋅
CrowdStrike
⋅
2021 Global Threat Report RansomEXX Amadey Anchor Avaddon BazarBackdoor Clop Cobalt Strike Conti Cutwail DanaBot DarkSide DoppelPaymer Dridex Egregor Emotet Hakbit IcedID JSOutProx KerrDown LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker NedDnLoader Nemty Pay2Key PlugX Pushdo PwndLocker PyXie QakBot Quasar RAT RagnarLocker Ragnarok RansomEXX REvil Ryuk Sekhmet ShadowPad SmokeLoader Snake SUNBURST SunCrypt TEARDROP TrickBot WastedLocker Winnti Zloader Evilnum OUTLAW SPIDER RIDDLE SPIDER SOLAR SPIDER VIKING SPIDER |
2021-02-22
⋅
tccontre Blog
⋅
Gh0stRat Anti-Debugging: Nested SEH (try - catch) to Decrypt and Load its Payload Ghost RAT |
2021-02-18
⋅
Symantec
⋅
Lazarus: Three North Koreans Charged for Financially Motivated Attacks AppleJeus POOLRAT Unidentified macOS 001 (UnionCryptoTrader) AppleJeus Unidentified 077 (Lazarus Downloader) |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048B): AppleJeus: JMT Trading AppleJeus AppleJeus |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048F): AppleJeus: Dorusio AppleJeus AppleJeus Unidentified 077 (Lazarus Downloader) |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048A): AppleJeus: Celas Trade Pro AppleJeus AppleJeus |
2021-02-17
⋅
US-CERT
⋅
Alert (AA21-048A): AppleJeus: Analysis of North Korea’s Cryptocurrency Malware AppleJeus AppleJeus Lazarus Group |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048G): AppleJeus: Ants2Whale AppleJeus AppleJeus |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048E): AppleJeus: CoinGoTrade AppleJeus POOLRAT AppleJeus |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048D): AppleJeus: Kupay Wallet AppleJeus AppleJeus |
2021-02-17
⋅
US-CERT
⋅
Malware Analysis Report (AR21-048C): AppleJeus: Union Crypto AppleJeus Unidentified macOS 001 (UnionCryptoTrader) AppleJeus |
2021-02-01
⋅
ESET Research
⋅
Operation NightScout: Supply‑chain attack targets online gaming in Asia Ghost RAT NoxPlayer Poison Ivy Red Dev 17 |
2021-02-01
⋅
One Night in Norfolk
⋅
DPRK Targeting Researchers II: .Sys Payload and Registry Hunting ComeBacker |
2021-01-30
⋅
⋅
Microstep Intelligence Bureau
⋅
Analysis of Lazarus attacks against security researchers ComeBacker |
2021-01-29
⋅
⋅
NSFOCUS
⋅
认识STUMBzarus——APT组织Lazarus近期定向攻击组件深入分析 ComeBacker DRATzarus Torisma |
2021-01-28
⋅
Microsoft
⋅
ZINC attacks against security researchers ComeBacker Klackring |
2021-01-27
⋅
S2W LAB Inc.
⋅
How to communicate between RAT infected devices (White paper) Volgmer |
2021-01-27
⋅
S2W LAB Inc.
⋅
Analysis of THREATNEEDLE C&C Communication (feat. Google TAG Warning to Researchers) Volgmer |
2021-01-26
⋅
One Night in Norfolk
⋅
DPRK Malware Targeting Security Researchers ComeBacker |
2021-01-26
⋅
Comae
⋅
PANDORABOX - North Koreans target security researchers ComeBacker |
2021-01-26
⋅
JPCERT/CC
⋅
Operation Dream Job by Lazarus LCPDot Torisma Lazarus Group |
2021-01-25
⋅
Google
⋅
New campaign targeting security researchers ComeBacker DRATzarus |
2021-01-20
⋅
JPCERT/CC
⋅
Commonly Known Tools Used by Lazarus Lazarus Group |
2021-01-15
⋅
Swisscom
⋅
Cracking a Soft Cell is Harder Than You Think Ghost RAT MimiKatz PlugX Poison Ivy Trochilus RAT |
2021-01-09
⋅
Marco Ramilli's Blog
⋅
Command and Control Traffic Patterns ostap LaZagne Agent Tesla Azorult Buer Cobalt Strike DanaBot DarkComet Dridex Emotet Formbook IcedID ISFB NetWire RC PlugX Quasar RAT SmokeLoader TrickBot |
2021-01-07
⋅
Github (hvs-consulting)
⋅
Lazarus / APT37 IOCs Lazarus Group |
2021-01-01
⋅
Objective-See
⋅
The Mac Malware of 2020 - a comprehensive analysis of the year's new malware AppleJeus Dacls EvilQuest FinFisher WatchCat XCSSET |
2020-12-23
⋅
Kaspersky Labs
⋅
Lazarus covets COVID-19-related intelligence BookCodes RAT wAgentTea |
2020-12-21
⋅
Cisco Talos
⋅
2020: The year in malware WolfRAT Prometei Poet RAT Agent Tesla Astaroth Ave Maria CRAT Emotet Gozi IndigoDrop JhoneRAT Nanocore RAT NjRAT Oblique RAT SmokeLoader StrongPity WastedLocker Zloader |
2020-12-18
⋅
Seqrite
⋅
RAT used by Chinese cyberspies infiltrating Indian businesses Ghost RAT |
2020-12-15
⋅
HvS-Consulting AG
⋅
Greetings from Lazarus: Anatomy of a cyber espionage campaign BLINDINGCAN MimiKatz Lazarus Group |
2020-12-15
⋅
HvS-Consulting AG
⋅
Greetings from Lazarus Anatomy of a cyber espionage campaign BLINDINGCAN HTTP(S) uploader MimiKatz |
2020-12-11
⋅
PWC UK
⋅
Tweet on macOS Manuscypt samples Manuscrypt |
2020-12-10
⋅
Intel 471
⋅
No pandas, just people: The current state of China’s cybercrime underground Anubis SpyNote AsyncRAT Cobalt Strike Ghost RAT NjRAT |
2020-12-10
⋅
US-CERT
⋅
Alert (AA20-345A): Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data PerlBot Shlayer Agent Tesla Cerber Dridex Ghost RAT Kovter Maze MedusaLocker Nanocore RAT Nefilim REvil Ryuk Zeus |
2020-12-09
⋅
CrowdStrike
⋅
From Zero to SixtyThe Story of North Korea’s Rapid Ascent to Becoming a Global Cyber Superpower FastCash Hermes WannaCryptor |
2020-11-27
⋅
⋅
Macnica
⋅
Analyzing Organizational Invasion Ransom Incidents Using Dtrack Cobalt Strike Dtrack |
2020-11-27
⋅
⋅
Microstep Intelligence Bureau
⋅
钱包黑洞:Lazarus 组织近期在加密货币方面的隐蔽攻击活动 Manuscrypt |
2020-11-21
⋅
vxhive blog
⋅
Deep Dive Into HERMES Ransomware Hermes |
2020-11-16
⋅
ESET Research
⋅
Lazarus supply‑chain attack in South Korea BookCodes RAT Lazarus Group |
2020-11-14
⋅
Medium 0xastrovax
⋅
Deep Dive Into Ryuk Ransomware Hermes Ryuk |
2020-11-12
⋅
Talos
⋅
CRAT wants to plunder your endpoints CRAT |
2020-11-05
⋅
McAfee
⋅
Operation North Star: Behind The Scenes NedDnLoader Torisma |
2020-11-03
⋅
Kaspersky Labs
⋅
APT trends report Q3 2020 WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX POISONPLUG Rover ShadowPad SoreFang Winnti |
2020-10-28
⋅
Twitter (@BitsOfBinary)
⋅
Tweet on macOS version of Manuscrypt Manuscrypt |
2020-10-27
⋅
Dr.Web
⋅
Study of the ShadowPad APT backdoor and its relation to PlugX Ghost RAT PlugX ShadowPad |
2020-10-03
⋅
VB Localhost
⋅
Unveiling the CryptoMimic CageyChameleon SnatchCrypto |
2020-09-29
⋅
JPCERT/CC
⋅
BLINDINGCAN - Malware Used by Lazarus BLINDINGCAN Lazarus Group |
2020-09-22
⋅
vmware
⋅
Detecting Threats in Real-time With Active C2 Information Agent.BTZ Cobalt Strike Dacls NetWire RC PoshC2 Winnti |
2020-09-16
⋅
Qianxin
⋅
Target defense industry: Lazarus uses recruitment bait combined with continuously updated cyber weapons CRAT |
2020-09-15
⋅
CrowdStrike
⋅
Nowhere to Hide - 2020 Threat Hunting Report NedDnLoader RDAT TRACER KITTEN |
2020-08-31
⋅
JPCERT/CC
⋅
Malware Used by Lazarus after Network Intrusion Lazarus Group |
2020-08-31
⋅
SentinelOne
⋅
The BLINDINGCAN RAT and Malicious North Korean Activity BLINDINGCAN |
2020-08-26
⋅
CISA
⋅
MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON PSLogger |
2020-08-26
⋅
CISA
⋅
Alert (AA20-239A): FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks FastCash |
2020-08-26
⋅
CISA
⋅
MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT NACHOCHEESE |
2020-08-19
⋅
US-CERT
⋅
Malware Analysis Report (AR20-232A) Bankshot BLINDINGCAN |
2020-08-19
⋅
CISA
⋅
MAR-10295134-1.v1 - North Korean Remote Access Trojan: BLINDINGCAN BLINDINGCAN |
2020-08-13
⋅
ClearSky
⋅
Operation ‘Dream Job’ Widespread North Korean Espionage Campaign DRATzarus LPEClient NedDnLoader |
2020-08-05
⋅
BlackHat
⋅
FASTCashand INJX_PURE: How Threat Actors Use Public Standards for Financial Fraud FastCash |
2020-08-05
⋅
BlackHat
⋅
FASTCash and Associated Intrusion Techniques FastCash |
2020-08-01
⋅
Temple University
⋅
Critical Infrastructure Ransomware Attacks CryptoLocker Cryptowall DoppelPaymer FriedEx Mailto Maze REvil Ryuk SamSam WannaCryptor |
2020-08-01
⋅
⋅
TG Soft
⋅
TG Soft Cyber - Threat Report DarkComet Darktrack RAT Emotet ISFB |
2020-07-29
⋅
ESET Research
⋅
THREAT REPORT Q2 2020 DEFENSOR ID HiddenAd Bundlore Pirrit Agent.BTZ Cerber ClipBanker CROSSWALK Cryptowall CTB Locker DanaBot Dharma Formbook Gandcrab Grandoreiro Houdini ISFB LockBit Locky Mailto Maze Microcin Nemty NjRAT Phobos PlugX Pony REvil Socelars STOP Tinba TrickBot WannaCryptor |
2020-07-29
⋅
Kaspersky Labs
⋅
APT trends report Q2 2020 PhantomLance Dacls Penquin Turla elf.wellmess AppleJeus Dacls AcidBox Cobalt Strike Dacls EternalPetya Godlike12 Olympic Destroyer PlugX shadowhammer ShadowPad Sinowal VHD Ransomware Volgmer WellMess X-Agent XTunnel |
2020-07-29
⋅
McAfee
⋅
Operation (노스 스타) North Star A Job Offer That’s Too Good to be True? NedDnLoader |
2020-07-28
⋅
Kaspersky Labs
⋅
Lazarus on the hunt for big game Dacls Dacls Dacls VHD Ransomware |
2020-07-28
⋅
⋅
NTT
⋅
CraftyPanda 標的型攻撃解析レポート Ghost RAT PlugX |
2020-07-27
⋅
SentinelOne
⋅
Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform AppleJeus Casso Dacls WatchCat |
2020-07-22
⋅
Kaspersky Labs
⋅
MATA: Multi-platform targeted malware framework Dacls Dacls Dacls |
2020-07-20
⋅
Risky.biz
⋅
What even is Winnti? CCleaner Backdoor Ghost RAT PlugX ZXShell |
2020-06-29
⋅
KISA
⋅
OPERATION BOOKCODES TTPs #2 BookCodes RAT |
2020-06-28
⋅
Twitter (@ccxsaber)
⋅
Tweet on Sample Unidentified 077 (Lazarus Downloader) |
2020-06-23
⋅
ReversingLabs
⋅
Hidden Cobra - from a shed skin to the viper’s nest Bankshot PEBBLEDASH TAINTEDSCRIBE |
2020-06-17
⋅
ESET Research
⋅
Operation In(ter)ception: Targeted Attacks against European Aerospace and Military Companies Interception |
2020-06-14
⋅
BushidoToken
⋅
Deep-dive: The DarkHotel APT Asruex Ghost RAT Ramsay Retro Unidentified 076 (Higaisa LNK to Shellcode) |
2020-06-09
⋅
Kaspersky Labs
⋅
Looking at Big Threats Using Code Similarity. Part 1 Penquin Turla CCleaner Backdoor EternalPetya Regin WannaCryptor XTunnel |
2020-06-05
⋅
Prevailion
⋅
The Gh0st Remains the Same Ghost RAT |
2020-06-04
⋅
PTSecurity
⋅
COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group Ghost RAT SongXY |
2020-05-31
⋅
Twitter (ShadowChasing1)
⋅
Tweet on DTRACK malware Dtrack |
2020-05-20
⋅
Medium Asuna Amawaka
⋅
What happened between the BigBadWolf and the Tiger? Ghost RAT |
2020-05-14
⋅
Avast Decoded
⋅
APT Group Planted Backdoors Targeting High Profile Networks in Central Asia BYEBY Ghost RAT Microcin MimiKatz Vicious Panda |
2020-05-12
⋅
US-CERT
⋅
MAR-10288834-1.v1 – North Korean Remote Access Tool: COPPERHEDGE Bankshot |
2020-05-11
⋅
Trend Micro
⋅
New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability Dacls |
2020-05-11
⋅
Trend Micro
⋅
New MacOS Dacls RAT Backdoor Show Lazarus’ Multi-Platform Attack Capability Dacls |
2020-05-07
⋅
AVAR
⋅
The North Korean AV Anthology: a unique look on DPRK’s Anti-Virus market Volgmer |
2020-05-06
⋅
Malwarebytes
⋅
New Mac variant of Lazarus Dacls RAT distributed via Trojanized 2FA app Dacls |
2020-05-05
⋅
Objective-See
⋅
The Dacls RAT ...now on macOS! deconstructing the mac variant of a lazarus group implant Dacls |
2020-05-04
⋅
ADEO DFIR
⋅
APT38 Lazarus Threat Analysis Report BLINDTOAD ELECTRICFISH |
2020-04-16
⋅
VMWare Carbon Black
⋅
The Evolution of Lazarus HOTCROISSANT Rifdoor |
2020-04-14
⋅
⋅
Qianxin
⋅
The Lazarus APT organization uses the new crown epidemic bait to target a targeted attack analysis of a country CRAT |
2020-04-09
⋅
⋅
suspected.tistory.com
⋅
Malware analysis (Emergency inquiry for Coronavirus response in Jeollanam-do.hwp) CRAT |
2020-04-01
⋅
KISA
⋅
OPERATION BOOKCODES TTPs #1 BookCodes RAT |
2020-03-05
⋅
Microsoft
⋅
Human-operated ransomware attacks: A preventable disaster Dharma DoppelPaymer Dridex EternalPetya Gandcrab Hermes LockerGoga MegaCortex MimiKatz REvil RobinHood Ryuk SamSam TrickBot WannaCryptor PARINACOTA |
2020-03-05
⋅
SophosLabs
⋅
Cloud Snooper Attack Bypasses AWS Security Measures Cloud Snooper Ghost RAT |
2020-03-03
⋅
PWC UK
⋅
Cyber Threats 2019:A Year in Retrospect KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle |
2020-02-26
⋅
MetaSwan's Lab
⋅
Lazarus group's Brambul worm |